Right then, grab yourself a cuppa and settle in, because we need to have a proper chat about internet privacy in 2026. I have been banging on about this stuff for the best part of a decade now, and honestly, the landscape has shifted so much in the last eighteen months that a lot of the advice I used to hand out is now about as useful as a chocolate fireguard. So here is me, sitting at my desk on a rainy Wednesday, trying to make sense of it all and pass on what actually still works.
Why 2026 feels different
I remember back in 2020 writing a piece about how trackers were getting cleverer, and thinking that was about as bad as it would get. How quaint that feels now. The truth is, the last couple of years have been a proper inflection point. Three things happened at once. Generative AI went mainstream and needed feeding. Governments around the world finally got their age verification and online safety acts through parliament. And the big browsers finished killing off third party cookies, which sounded lovely until you realised what replaced them was in many ways sneakier.
Put those three together and you get a web where your face, your voice, your browsing habits, your location pings and your slightly embarrassing 2am searches are all being ingested, correlated and monetised in ways that would have made a 2015 adtech bro weep with envy. And yet most people are still using the same password from 2014 and clicking accept on every cookie banner they see. Which, fair play, is a perfectly reasonable response to being exhausted. But it is not going to help you.
So let us walk through what is actually going on, and then I will tell you what I am personally doing about it. No silver bullets, no affiliate links to overpriced VPNs, just what works for a regular person trying to keep a bit of dignity online.
The big problems we are dealing with
AI is hoovering up everything
This is the elephant in the room, and it is a big one. Every major AI provider is scraping the public web at a scale that is frankly hard to comprehend. Your old blog posts, your forum comments from 2012, your Flickr photos with your kids in them, your GitHub repos, your Reddit rants. All of it is fair game unless you have explicitly opted out, and even then, good luck enforcing it.
The newer problem, though, is the second order stuff. AI assistants on your phone are now summarising your emails, reading your calendar, and in some cases transcribing your voice memos to send to the cloud for processing. The on device AI story that Apple and Google have been pushing is real, but only up to a point. The moment you ask your phone something slightly complicated, off it goes to a datacentre somewhere. And the terms around what gets retained for training are, to be generous, a bit vague.
Then you have the synthetic identity side of things. Deepfakes are no longer a novelty, they are a nuisance. I have had two mates in the last six months get targeted by voice cloning scams where someone phoned pretending to be a relative in trouble. The voice was good. Properly unsettling. Privacy in 2026 is no longer just about who sees your data, it is about whether your data can be used to impersonate you convincingly.
Age verification and digital ID
Here in the UK, the Online Safety Act is now in full swing, and similar rules have landed across the EU and in a growing number of US states. The upshot is that an awful lot of the web now wants to see some ID before it lets you in. Social platforms, adult content sites, certain forums, even some comment sections. The methods vary from the mildly annoying to the genuinely dystopian.
Some sites use age estimation from a selfie, which means you are handing a biometric scan to a third party you have never heard of. Others want you to upload a photo of your driving licence. A few are pushing you towards government backed digital ID wallets. Each of these approaches creates a new database somewhere that links your real identity to your online activity. And databases, as we have learnt again and again, leak.
The chilling effect is real too. I have noticed myself hesitating before posting on certain forums now, knowing that my account is tied to my actual face. That hesitation is the point, whether the policymakers will admit it or not.
The post cookie tracking nightmare
Third party cookies are basically dead in Chrome now, which was supposed to be the big privacy win. What replaced them is a mix of first party tracking, server side fingerprinting, Google's Topics API and various cohort based systems that are honestly harder to block than the old cookies ever were. Your browser is still leaking a fingerprint, and that fingerprint is still unique enough to follow you around.
Add to that the rise of privacy sandbox style APIs that let advertisers infer your interests without technically storing a cookie, and you have a situation where the tracking is just as pervasive but now it lives inside the browser itself rather than on top of it. Blocking it requires more than just installing an extension, especially now that Manifest V3 has properly kneecapped the ad blockers on Chrome.
Your home is listening
I know, I know, we have been saying this for years. But 2026 is the year where the smart home has genuinely gone mainstream, and the data sharing arrangements have got properly murky. Smart TVs are now basically ad networks with a screen attached. Doorbell cameras are sharing footage with law enforcement in ways that vary wildly depending on the brand and the country you live in. Voice assistants are processing more locally than they used to, but the wake word detection still happens in the cloud for a lot of devices.
The thing that really bothers me is the aggregation. Your thermostat knows when you are home, your doorbell knows who visits, your smart speaker knows what you argue about, your robot vacuum knows the layout of your flat. None of those individually are catastrophic. Put them together under one account and you have built a surveillance profile of yourself that most intelligence agencies would have killed for twenty years ago.
Encryption is under siege
The client side scanning debate has not gone away, it has just got quieter and more insidious. The UK government has not dropped its desire to be able to peer into end to end encrypted messaging, and similar pressures are building in Australia, the US and parts of the EU. What we are seeing now is less about outright bans and more about platforms quietly adding scanning on their own side of the connection, before the encryption kicks in. Upload scanning, attachment scanning, hash matching on media before it leaves your device. The maths of end to end encryption is still solid. The politics of it is getting properly wobbly.
What actually still works in 2026
Right, enough doom and gloom. Here is what I am personally doing, and what I recommend to anyone who asks. None of this is revolutionary, but together it adds up to a meaningful reduction in your exposure.
Your browser is your first line of defence
If you are still using Chrome as your daily driver, I would gently suggest you stop. Not because Chrome is evil, but because Manifest V3 has genuinely hobbled the ad blocking ecosystem on it, and Google's commercial incentives are always going to pull it in the direction of advertiser friendly privacy rather than user friendly privacy.
My own setup in 2026 is Firefox with a curated set of extensions for desktop, and Brave or a hardened Firefox fork on mobile. The extensions that actually still do meaningful work are uBlock Origin, which somehow keeps surviving despite all the attempts to neuter it, a decent content blocker for tracker lists, and ClearURLs to strip the tracking parameters off links. I also use the Multi Account Containers extension to keep my banking, social media and general browsing in separate little sandboxes. It is a faff at first, but you get used to it.
On the fingerprinting front, the best defence is honestly to look as boring and generic as possible. Resist the urge to install seventeen quirky extensions, because each one makes your browser more unique. A stock Firefox with uBlock Origin and default settings is paradoxically more private than a heavily tweaked setup.
Search engines that do not spy
I bounced between DuckDuckGo, Brave Search and Startpage for years, and have settled on a mix. Brave Search for most queries because the results have got genuinely good and it does not log. Startpage as a fallback when I want Google quality results without the Google tracking. Kagi if I am feeling fancy and want something ad free with decent customisation, though it costs a few quid a month.
The bigger trick, though, is learning to not search for everything. A lot of my queries now go straight to specific sites. Wikipedia, Reddit, specific subreddits, Hacker News, the documentation for whatever tool I am using. Every time you avoid the search engine middleman, you avoid the profiling that comes with it.
Email aliases are now mandatory in my book
This is the single biggest upgrade I have made in the last couple of years. I no longer give out my real email address to almost anyone. Instead, I use an aliasing service. SimpleLogin and Addy.io are the two I rotate between, and Apple's Hide My Email does a decent job if you are deep in the Apple ecosystem.
The idea is simple. Every service you sign up for gets its own unique email address that forwards to your real inbox. If one of those services gets breached, or sells your data, or starts spamming you, you just kill that alias. You also get to see exactly who is sharing your details, because when an alias you gave to Company A suddenly starts receiving mail from Company B, you know something dodgy is going on.
Pair this with a proper password manager and you have compartmentalisation that would have taken a spy to set up ten years ago, and now it takes about ten minutes.
Passkeys, passwords and the mess in between
Passkeys have finally started to actually work in 2026, after a few years of being more promise than reality. For the big services, Google, Apple, Microsoft, GitHub, the big banks, I have switched over. The experience is genuinely good, and the security is miles better than any password I could remember.
But passkeys are not a privacy panacea, and this is the bit most articles gloss over. When you use a passkey tied to your Apple or Google account, you are now relying on those companies to authenticate you everywhere. That is a lot of trust in one basket. So my rule is that for anything sensitive, banking, email, messaging, password manager, I still use a strong unique password generated by my password manager, with a hardware security key as the second factor. Bitwarden, 1Password, the usual suspects are all still fine. Just pick one and actually use it.
Messaging that actually keeps its mouth shut
Signal is still my default for private conversations, and I cannot see that changing any time soon. The protocol is solid, the metadata is minimal, and they have a track record of fighting subpoenas properly. For group chats with folks who will never install Signal, I have given up and use WhatsApp, but I treat it as a public channel. Nothing sensitive, nothing I would mind a bored contractor reading.
Telegram is popular but the default chats are not end to end encrypted, which still catches people out. iMessage is decent between Apple users but the iCloud backup loophole is a real thing, so turn that off if you care. And please, for the love of everything, stop sending sensitive stuff over Instagram DMs or Facebook Messenger. Those are not private channels in any meaningful sense.
VPNs, DNS and the boring plumbing
I am going to be honest here. VPNs are oversold. They do not make you anonymous, they do not magically encrypt your entire life, and a lot of the popular ones have appalling privacy records. What a good VPN does do is hide your browsing from your ISP and let you appear to be in a different country, which is still useful.
For most people, I would say the more important thing is encrypted DNS. Setting up DNS over HTTPS on your router, or using a privacy focused provider like Quad9, NextDNS or Mullvad's DNS, stops your ISP from casually logging every domain you visit. It is five minutes of work and it closes one of the biggest remaining visibility holes.
If you do want a VPN, pick one that has been independently audited, accepts anonymous payment, and has a genuine no logs policy that has been tested in court. Mullvad, IVPN and ProtonVPN are the ones I would put my name behind. Avoid the ones that advertise on podcasts and YouTube, almost to a rule.
Mobile privacy, the forgotten battleground
Your phone is the most surveilled device you own, full stop. It knows where you are, who you talk to, what you buy, how many hours you slept, and in some cases how fast your heart is beating. Taming it is a proper project.
On iPhone, the basics are still solid. Turn off unnecessary location permissions, disable Significant Locations, turn off analytics sharing, use App Tracking Transparency properly and say no to almost everything. On Android, you have more options but also more rope to hang yourself with. A GrapheneOS or CalyxOS install on a Pixel is still the gold standard if you are technical and want to go the whole hog. For everyone else, a stock Android with permissions ruthlessly pruned and a sandboxed Play Services setup is a reasonable middle ground.
The one thing I would push everyone to do is audit your app permissions once a quarter. You will be horrified at what you have granted and forgotten about. That torch app does not need your contacts. That parking meter app does not need your location when it is closed.
Smart homes, dumb decisions
My approach here is brutally simple. If a device does not genuinely need the internet to do its job, it does not get internet access. I have a separate VLAN for IoT devices, and they are blocked from talking to anything except the specific cloud endpoints they need. My robot vacuum is on this network. My smart bulbs are on this network. My doorbell, which I am still slightly conflicted about, is on this network and its recordings are set to delete after a week.
Where I can, I have switched to local control. Home Assistant running on a little Raspberry Pi style box handles most of my automation now, talking to Zigbee and Matter devices directly without phoning home. It took a weekend to set up and it is genuinely better than any of the commercial offerings, plus it keeps my data inside my house where it belongs.
For anything that absolutely must talk to the cloud, I pick brands that have a credible privacy story and ideally end to end encryption on the video and audio. They are rare, but they exist.
The mindset shift nobody talks about
Here is the bit that took me years to internalise. Perfect privacy in 2026 is not a thing. If you try to achieve it, you will burn out in six months and go back to clicking accept on every banner. The goal is not invisibility, it is reducing your surface area to a level you are comfortable with.
Think of it like home security. You do not need a panic room and armed guards. You need good locks, decent lights, and neighbours who notice things. Same principle. Get the basics right, keep an eye on the big risks, and accept that some amount of tracking is the price of using the modern web.
The other mindset shift is about value. Your data is worth something, and a lot of services are offering you a terrible deal for it. Once you start thinking in those terms, you start making different choices. You pay a few quid for Kagi instead of giving Google another data point. You use Signal instead of Messenger. You buy a dumb kettle instead of one that wants your WiFi password. Small choices, but they add up.
Wrapping up
Look, I know this is a lot. If you take nothing else away, take these five things and do them this weekend.
- Switch to Firefox or Brave and install uBlock Origin.
- Set up an email aliasing service and start using it for new signups.
- Get a proper password manager and turn on two factor authentication everywhere.
- Install Signal and use it for the conversations that matter.
- Audit your phone permissions and turn off the nonsense.
That alone will put you ahead of ninety five percent of people online. The rest is polish, and you can layer it on as you go.
Privacy in 2026 is harder than it has ever been, but it is not hopeless. The tools are better than they were five years ago, the awareness is higher, and there is a genuine community of people working on this stuff because they think it matters. I am one of them, and if you have read this far, I suspect you might be too.
Stay safe out there, and for goodness sake change that password you have been using since 2014. You know the one.
Switch to Firefox or Brave and install uBlock Origin.
Set up an email aliasing service and start using it for new signups.
Get a proper password manager and turn on two factor authentication everywhere.
Install Signal and use it for the conversations that matter.
Audit your phone permissions and turn off the nonsense.
That alone will put you ahead of ninety five percent of people online. The rest is polish, and you can layer it on as you go.
Privacy in 2026 is harder than it has ever been, but it is not hopeless. The tools are better than they were five years ago, the awareness is higher, and there is a genuine community of people working on this stuff because they think it matters. I am one of them, and if you have read this far, I suspect you might be too.
Stay safe out there, and for goodness sake change that password you have been using since 2014. You know the one.

Top comments (0)